y1ong / blog-timeline

个人博客bb空间
MIT License
11 stars 0 forks source link

Ivanti Pulse Connect Secure VPN 远程代码执行(CVE-2023-46805) #357

Open y1ong opened 9 months ago

y1ong commented 9 months ago

漏洞描述
2024年互联网上披露CVE-2023-46805 Ivanti Pulse Connect Secure VPN 远程代码执行,攻击者可构造恶意请求绕过身份认证,结合相关功能造成远程代码执行。

参考链接

  1. https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US